Aggregator
CVE-2026-2756 | OmniPEMF NeoRhythm up to 20260308 BLE Interface missing authentication (EUVD-2026-14254)
4 weeks 1 day ago
A vulnerability, which was classified as critical, was found in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2026-2756. The attack can only be initiated within the local network. No exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-4555 | D-Link DIR-513 1.10 boa formEasySetTimezone curTime stack-based overflow
4 weeks 1 day ago
A vulnerability, which was classified as critical, has been found in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2026-4555. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
Submit #774937: OmniPEMF NeoRhythm U-BAND Missing Authentication for Critical Function [Accepted]
4 weeks 1 day ago
Submit #774937 / VDB-352383
drewbug
CVE-2026-4554 | Tenda F453 1.0.0.3 /goform/WriteFacMac FormWriteFacMac mac command injection
4 weeks 1 day ago
A vulnerability classified as critical was found in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection.
This vulnerability is known as CVE-2026-4554. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
CVE-2026-4553 | Tenda F453 1.0.0.3 Parameters /goform/Natlimit fromNatlimit page stack-based overflow
4 weeks 1 day ago
A vulnerability classified as critical has been found in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-4553. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2026-4552 | Tenda F453 1.0.0.3 Parameters /goform/VirtualSer fromVirtualSer page stack-based overflow
4 weeks 1 day ago
A vulnerability described as critical has been identified in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2026-4552. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2026-4551 | Tenda F453 1.0.0.3 Parameters /goform/SafeClientFilter fromSafeClientFilter menufacturer/Go stack-based overflow
4 weeks 1 day ago
A vulnerability marked as critical has been reported in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-4551. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
Submit #774936: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Accepted]
4 weeks 1 day ago
Submit #774936 / VDB-352382
LtzHust2
Submit #774935: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Duplicate]
4 weeks 1 day ago
Submit #774935 / VDB-352009
LtzHust2
12 часов тишины против солнечной короны: миссия Proba-3 едва не погибла в шаге от главного открытия в физике звезд
4 weeks 1 day ago
Дрейфующий в космосе зонд вернулся к жизни под присмотром своего неразлучного спутника.
Submit #774933: Tenda F453 v1.0.0.3 Command Injection [Accepted]
4 weeks 1 day ago
Submit #774933 / VDB-352381
LtzHust
Submit #774931: Tenda F453 v1.0.0.3 Stack-based Buffer Overflow [Accepted]
4 weeks 1 day ago
Submit #774931 / VDB-352380
LtzHust
Submit #774930: Tenda F453 v1.0.0.3 Stack-based Buffer Overflow [Accepted]
4 weeks 1 day ago
Submit #774930 / VDB-352379
LtzHust
Submit #774929: Tenda F453 v1.0.0.3 Stack-based Buffer Overflow [Accepted]
4 weeks 1 day ago
Submit #774929 / VDB-352378
LtzHust
CVE-2026-4550 | code-projects Simple Gym Management System up to 1.0 /gym/func.php Trainer_id/fname sql injection
4 weeks 1 day ago
A vulnerability labeled as critical has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection.
This vulnerability is documented as CVE-2026-4550. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
Submit #774932: Tenda F453 v1.0.0.3 Stack-based Buffer Overflow [Duplicate]
4 weeks 1 day ago
Submit #774932 / VDB-348263
LtzHust
Submit #774928: Tenda F453 v1.0.0.3 Stack-based Buffer Overflow [Duplicate]
4 weeks 1 day ago
Submit #774928 / VDB-348262
LtzHust
CVE-2026-4549 | mickasmt next-saas-stripe-starter 1.0.0 Stripe API open-customer-portal.ts openCustomerPortal authorization
4 weeks 1 day ago
A vulnerability identified as critical has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass.
This vulnerability is registered as CVE-2026-4549. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-4548 | mickasmt next-saas-stripe-starter 1.0.0 update-user-role.ts updateUserrole userId/role improper authorization (EUVD-2026-14306)
4 weeks 1 day ago
A vulnerability categorized as critical has been discovered in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization.
This vulnerability is cataloged as CVE-2026-4548. The attack may be launched remotely. There is no exploit available.
vuldb.com